Collection

Breach, Exposure, and Attack Surface Research Toolkit

Editorial 16 tools 3 curated picks

A practical stack for confirming breach chatter and expanding it into external exposure context.

Stack snapshot

16 tool profiles in this workflow, including 3 curated picks.

Best for

Security teams, journalists, and investigators triaging breach signals, suspicious indicators, or external exposure around a company or identity.

Methodology

The stack starts with conservative confirmation and adds depth only when the lead justifies it, reducing overreaction to noisy exposure chatter.

Editorial note

Placement reflects corroboration value and workflow fit, not vendor prestige or product pricing.

Curated picks

Top pick

Shodan

Budget pick

Have I Been Pwned

Open-source pick

SpiderFoot

Stack tools

Tools in this workflow

Scan the stack, then open profiles for caveats, pricing, and disclosure context.

Tool profile

Have I Been Pwned

Breach exposure lookup for emails and domains

Tested

Tool profile

Hudson Rock Exposure Intelligence

Infostealer exposure intelligence

Affiliate

Tool profile

URLhaus

Malware-URL intelligence reference

Editorial

Tool profile

PhishTank

Community phishing URL verification

Editorial

Tool profile

Cisco Talos Intelligence

IP, domain, and email reputation intelligence

Editorial

Tool profile

AlienVault OTX

Open threat-intelligence community pulses

Editorial

Tool profile

VirusTotal

Multi-source reputation context for indicators

Editorial

Tool profile

AbuseIPDB

IP abuse-report and reputation lookup service

Editorial

Tool profile

GreyNoise

Background internet noise intelligence

Sponsored

Tool profile

Shodan

Public-internet exposure search for hosts and services

Tested

Tool profile

Censys

Structured search for hosts, services, and certificates

Tested

Tool profile

urlscan.io

URL render, screenshot, and network trace capture

Editorial

Tool profile

Hybrid Analysis

Malware-analysis report community

Editorial

Tool profile

ANY.RUN

Interactive threat-analysis sandbox

Editorial

Tool profile

CyberChef

Browser-based data decoding and transformation

Editorial

Tool profile

SpiderFoot

Automated OSINT collection for scoped leads

Tested

Workflow notes

This collection is built for operators who need to move from a breach rumor, exposed credential clue, or suspicious external signal into a more defensible picture of risk.

Use this stack when

The case needs conservative breach confirmation, infostealer exposure context, suspicious-indicator review, internet-noise triage, or external attack-surface clues.

Recommended sequence

  • Start with Have I Been Pwned for a conservative breach confirmation step.
  • Use Hudson Rock when infostealer-style exposure or employee-device context matters.
  • Bring in Intelligence X for older, broader, or harder-to-find leak-adjacent traces.
  • Use VirusTotal when the lead is a suspicious URL, domain, IP, or hash that needs reputation context.
  • Use GreyNoise to separate noisy internet scanning from more interesting infrastructure signals.
  • Use Shodan to map exposed hosts and services tied to the organization.
  • Use urlscan.io when suspicious pages, landing pages, or web infrastructure need a preserved snapshot.

Editorial guardrail

This is not incident response in a box. Exposure signals can involve victims and sensitive data, so publish only conservative claims that survive source and authorization review.